Safety PLC Reprogramming Guarded by Majority Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial safety systems in plants are vulnerable to cyber-attacks, which can compromise safety PLCs and lead to catastrophic accidents by allowing malicious applications to reprogram them, as they lack robust authentication mechanisms.

Innovation Solution

Implementing a secure network of safety PLCs that employs multi-PLC verification through authentication challenges and proof-of-work (PoW) to ensure that only verified programming applications can reprogram the PLCs, requiring a majority of the PLCs to verify the authenticity before allowing updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If safety PLCs allow reprogramming by authorized applications, then the system maintains adaptability and can be updated, but the system becomes vulnerable to cyber-attacks and malicious reprogramming

Engineering Contradiction:
Improvereprogramming capabilityVSAvoidcyber-attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication and verification actions before allowing reprogramming. Multiple safety PLCs verify the programming application in advance through authentication challenges and proof-of-work computations, ensuring that malicious applications are blocked before they can compromise the safety PLCs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism where multiple safety PLCs act as mediators between the programming application and the target safety PLC. These intermediary PLCs validate the application through authentication challenges and coordinate to prevent unauthorized reprogramming, adding a layer of security without blocking legitimate updates.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the system implements multi-PLC verification with authentication challenges, then security against cyber-attacks is improved, but the complexity of the reprogramming process increases

Engineering Contradiction:
Improvecyber-attack resistanceVSAvoidauthentication process complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The authentication process is segmented into distinct phases: authentication challenge issuance, proof-of-work computation, verification, and coordinated approval. Multiple safety PLCs are segmented into verifying and target PLCs, with clear division of responsibilities. This segmentation makes the complex authentication process more manageable and systematic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes parameters such as authentication challenge types, proof-of-work difficulty levels, and verification thresholds to balance security and complexity. By adjusting these parameters, the system can enhance security against cyber-attacks while managing the operational complexity of the authentication process.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12007740B2Secure network of safety PLCs for industrial plants
Publication Date: 2024.06.11 SCHNEIDER ELECTRIC SYSTEMS USA INC
  • US12007740B2 patent drawing
  • US12007740B2 patent drawing
  • US12007740B2 patent drawing

AI summary

Network of safety PLCs employs multi-PLC verification of a programming application before allowing the application to reprogram any PLC on the safety network. Each PLC on the safety network is equipped with authentication capability that detects attempts to reprogram the PLC and issues an authentication challenge requiring the programming application to process a proof-of-work. The authentication challenge is also sent to other PLCs on the safety network along with the response from the programming application for verification purposes. The other PLCs process the authentication challenge and check the response from the programming application for acceptability. If a majority of the PLCs on the safety network determines the response from the programming application is correct, then the programming application is verified and may proceed with the reprogramming. Such group authentication requires a malicious application to hijack multiple PLCs concurrently on the safety network, a highly unlikely outcome, before reprogramming any PLC.